KUALA LUMPUR, 11 March 2026 – Companies across the Asia-Pacific region are facing a sharp rise in insider-driven cyber incidents, highlighting growing vulnerabilities as organisations accelerate digital transformation and AI adoption.
The latest findings show that insider-related cyber threats are occurring more frequently in APAC than in North America, underscoring a shifting risk landscape where employees, contractors and internal users are increasingly at the centre of cybersecurity breaches.
Insider Threats Becoming a Key Risk Driver
Cybersecurity experts warn that insider threats, whether malicious or accidental, are emerging as one of the most difficult risks to manage.
Unlike external attacks, insider incidents often involve legitimate access credentials, making them harder to detect and prevent. These threats can stem from:
- Negligent handling of sensitive data
- Misconfigured access permissions
- Compromised employee accounts
- Intentional misuse of systems
As organisations expand their digital infrastructure, the number of access points, including employees, vendors and automated systems, continues to grow, increasing the attack surface.
AI and Digital Expansion Amplify Risks
The surge in incidents is closely linked to the rapid adoption of artificial intelligence and cloud-based systems across the region.
As enterprises deploy AI tools, automation and digital workflows, they are creating new layers of identity and access complexity, often without corresponding improvements in governance and security controls.
This trend aligns with broader cybersecurity observations that AI is a double-edged sword — enhancing both defensive capabilities and the sophistication of cyberattacks.
Asia-Pacific a Prime Target
Asia-Pacific’s rapid economic growth and digitalisation have made it a prime target for cyber threats.
The region’s diverse markets, expanding digital ecosystems and increasing cross-border business activity have created high-value targets for cybercriminals, particularly in sectors such as finance, government and critical infrastructure.
At the same time, uneven cybersecurity maturity across countries has made some organisations more vulnerable to internal and external threats.
Governance and Human Risk in Focus
The findings reinforce a growing industry consensus: humans remain the weakest link in cybersecurity.
As a result, companies are increasingly prioritising:
- Identity governance and access control frameworks
- Employee cybersecurity awareness training
- Real-time monitoring of user activity
- Zero-trust security architectures
Experts say organisations must move beyond traditional perimeter-based security models and adopt identity-centric approaches that monitor behaviour and access patterns continuously.
Rising Regulatory and Insurance Pressure
Governments across Asia-Pacific are also tightening cybersecurity regulations, requiring organisations to strengthen risk management and incident reporting frameworks.
This has led to increased demand for cyber insurance and compliance solutions, particularly among large enterprises operating across multiple jurisdictions.
A Growing Strategic Risk
As insider-driven incidents continue to rise, cybersecurity is no longer just an IT issue but a board-level priority for organisations across the region.
With AI accelerating both innovation and risk, companies are being forced to rethink how they manage identity, access and human behaviour within their digital ecosystems.
The surge in insider threats signals a critical shift in the cyber risk landscape, one where the greatest vulnerabilities may already exist within the organisation itself.